Post-quantum cryptography migration allows a reassessment of cybersecurity.

Quantum computers are rapidly approaching the capability to break existing cryptographic algorithms, including public key encryption. This moment, referred to as “Q-Day,” is becoming imminent as advancements in computing power make post-quantum threats increasingly tangible. Some security experts predict Q-Day could occur within the next decade, leaving digital information vulnerable under current encryption protocols.

Post-quantum cryptography (PQC) is designed to withstand future post-quantum threats and attacks, making it a priority in the cybersecurity agenda. Transitioning to PQC not only protects data and systems but also provides an opportunity to reassess the broader cybersecurity landscape.

Cyber Security Hub interviewed renowned cybersecurity academic Professor Alan Woodward from the School of Electronic Engineering and Computer Science at the Surrey Centre for Cyber Security, University of Surrey, to discuss the importance of PQC migration and the shift to quantum-resistant encryption.

Cyber Security Hub: How will quantum computing impact enterprise cybersecurity?

Professor Alan Woodward: The most well-known security threat from quantum computing is that various public key encryption schemes currently in use can be broken using an algorithm developed by Peter Shor in 1996. Shor’s algorithm can break cryptographic methods based on the hidden subset problem, such as RSA and ECC, but does not affect symmetric encryption like AES. Grover’s Algorithm, another quantum algorithm, can brute force keys in some symmetric encryption, but its speed is not as exponential as Shor’s algorithm.

CSH: How critical is PQC for the future of cybersecurity?

AW: PQC is essential for mitigating the risks posed by Shor’s algorithm. This is why the US National Institute of Standards and Technology (NIST) held a competition to select new quantum-resistant standards for public key encryption. Many vendors are already releasing products utilizing these new PQC schemes. Organizations must replace their current public key infrastructure and products using public key encryption to avoid the risk of their sensitive data being exposed or browser sessions being eavesdropped on.

CSH: Should organizations start preparing for PQC migration now?

AW: Although no quantum computer currently exists that can run Shor’s algorithm at a scale large enough to break present public key encryption, a malicious actor might be collecting encrypted data now, anticipating the future availability of such a quantum computer. The risk to organizations depends on the longevity of the data protected by encryption. The UK National Cyber Security Centre (NCSC) offers extensive advice for companies on migrating to PQC. I recommend organizations follow this advice and act promptly. The guidance is pragmatic, acknowledging that migration won’t occur overnight, but emphasizes the need for organizations to start now to be ready and mitigate the risk of data being collected for future decryption.

CSH: What will be the biggest challenges of PQC migration for most businesses?

AW: The primary challenge will be implementing PQC while maintaining interoperability with organizations and users who haven’t yet updated to PQC. This situation risks a downgrade attack, where attackers force you to revert to older cipher suites retained for backward compatibility. Deciding when to phase out these historical cipher suites will be difficult. There will always be laggards, and businesses must determine whether to accommodate them at the risk of compromising their encryption.

CSH: How can businesses best prepare for PQC migration, and what factors are most important?

AW: Each organization will have a unique approach to migration. The first step is identifying where potentially vulnerable public key encryption is being used, including in less obvious products like tape backup systems. Once identified, organizations need to develop a change program for these elements under their control and consult with product vendors to understand their plans for upgrading to PQC.

More Articles & Posts